126 Accounts Exposed in ‘DARK HoTM’ Hotmail Combolist Leak
On 6 August 2026, a combolist titled "DARK HoTM" was uploaded to Telegram. HEROIC's monitoring confirmed the file contains exactly 126 records, each pairing an email address with a plaintext password and an associated URL.
Why This Is Dangerous
A small record count doesn't mean small risk. Each of these 126 entries includes a plaintext password, ready to use without any cracking, and the "HoTM" in the file name suggests the credentials target Hotmail or similar webmail accounts, which are frequently used to recover access to other services.
What Was Exposed
The "DARK HoTM" combolist contains:
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
Webmail credentials like these are a prime target for credential stuffing and account takeover because email inboxes are often the gateway to resetting passwords on banking, shopping, and social media accounts. Anyone among these 126 records who reused their password is at heightened risk of identity theft.
How This Combolist Was Built
Combolists like "DARK HoTM" are typically compiled from older breaches, phishing pages, or malware infections, then packaged under an attention-grabbing name and shared on Telegram. Even relatively small files like this one circulate quickly once uploaded, often getting copied and re-shared across multiple channels.
Check If You Are Affected
With 126 confirmed records in this leak, checking your exposure takes only seconds. HEROIC's free breach scanner searches more than 400 billion leaked records, including this combolist, so you can act before someone else does.
Breach Breakdown
126 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds